In the morning a campaign burned through half its daily budget in an hour, with three times the usual clicks and zero leads. Sometimes it is a broken offer; sometimes it is click fraud: someone deliberately clicking your ads so you pay for empty visits. It hurts most on pay-per-click models, where every fake click is charged directly.
What is click fraud
Click fraud in the narrow sense means deliberate clicks on ads with no interest in the offer. In the broader sense it covers any fraudulent clicks, including inflation by placements, botnets and "farms" of people paid to click. Systems that catch all types of ad fraud are called anti-fraud systems.
It is important to tell click fraud from ordinary bot traffic. A platform robot checking your link or a crawler building a preview is not a person either, but it is not trying to spend your budget. Bot traffic signs in general are covered in bot traffic: how to recognize it.
Who commits click fraud
| Who | Why | What it usually looks like |
|---|---|---|
| Competitors | Burn your budget and push you out of the auction | Manual clicks or simple bots, often early in the day |
| Publishers in ad networks | Earn from clicks on your ads | Inflation on specific sites and zones |
| Botnets | Sell "traffic" or inflate metrics | Many addresses, uniform browsers |
| Click farms | Imitate real people for money | Real devices, zero engagement |
| Disgruntled users | Annoy the advertiser | Occasional repeat clicks |
In search and social advertising the first type is more common; in native, push and popunder, the second and third. The specifics of those formats are covered in push and pop traffic: how to cut bots.
Click farms deserve a separate word. Real people click on real phones there, so network and browser checks often miss them: the device is genuine, the network is mobile, JavaScript runs. What gives them away is behavior and stats: instant exits, no scrolling, bursts of clicks in the same minutes, zero conversions on noticeable volume. Against farms, placement analysis and turning off the source work best, rather than trying to catch every click. How device farms and emulators work in apps is covered in in-app traffic and fraud.
Signs of click fraud in your stats
An abnormal rise in clicks without conversions
The most obvious symptom. It is especially telling when clicks rise rather than impressions: CTR shoots up for no visible reason.
Repeats from the same addresses and subnets
A real person clicks one ad once or twice. A series of clicks from one IP or neighboring addresses in one subnet is almost certainly fraud.
Time patterns
- clicks concentrated in the first hours of the ad account's day, before the budget runs out;
- even intervals between clicks;
- activity at night in a geo where everyone is asleep.
Uniformity
Hundreds of "different" visitors with one device model, one browser version, one screen resolution.
Zero engagement
Zero time on page, no movement, not a single action beyond the first screen.
Concentration on placements
In networks that place ads on partner sites, fraud is almost always concentrated on particular placements or zones. If one zone delivers a third of the clicks and not a single lead, the answer is obvious.
Tip. To see placements, pass the zone, site or placement ID into a campaign parameter, for example
sub1={zoneid}. More on parameters and macros in UTM parameters and ad platform macros.
How to prevent click fraud: what works
First, the main limitation: the click is charged on the platform's side the moment it happens. No filter on your site can "cancel" the charge. Protection works differently: it reduces the damage and gives you data to shut off the source.
1. A filter at the entrance
A traffic filter keeps fraud off the offer. This matters more than it seems:
- fraud does not reach the affiliate network or spoil your approval rate;
- fake clicks do not distort the offer stats, so you do not make decisions based on noise;
- you see what share of paid traffic was fraud, and with which signs.
The general approach is in how to filter bot traffic.
2. A per-IP click limit
A limit on the number of visits from one IP per day cuts the most common form of click fraud: repeated clicks by one person or bot. Set it with headroom: mobile carriers and offices can have many people behind one address.
3. Exclusions in the ad account
Most platforms let you exclude IP addresses, sites, placements or zones. Take the data for exclusions from the visit log: addresses, subnets, zone IDs.
4. Targeting and schedule
A narrow geo and a delivery schedule shrink the window for fraud. If your audience is active during the day, night-time impressions are extra risk. More in filtering by geo, language, device and schedule.
5. An address blacklist
A specific persistent competitor is easiest to put on your own IP blacklist: they will see a neutral page and lose track of what you are running.
6. A refund request
If the share of fraud is significant, gather the data — times, addresses, networks, filtering reasons — and file a request with the platform's support. The more specific the data, the better the chance of compensation.
Click fraud on different platforms
The nature of click fraud depends heavily on where you buy traffic.
| Platform type | What is more common | What to watch |
|---|---|---|
| Search (Google Ads, Microsoft Ads and others) | Competitor clicks on expensive keywords | Repeats from the same addresses, clicks early in the day |
| Social (Facebook, TikTok and others) | Less direct click fraud, more reviews and bots | Visits without a click ID, hosting networks |
| Native networks | Inflation on particular partner sites | Clicks concentrated on placements and zones |
| Push and popunder | Botnets, fraudulent subscriptions | Uniform devices, zero time on page |
In search advertising the main adversary is a competitor, and a per-address click limit and a blacklist work well here (for Yandex search and its ad network, see click fraud in Yandex Direct). In native and push it is dishonest placements, and the main tool is the zone report and blocking junk sites in the ad network itself. Each platform's specifics are collected in the traffic source catalog.
Why the click ID matters
Platforms pass the ad click ID in the link: gclid, fbclid, ttclid, yclid and others. A visit without such an ID on a click from an ad deserves a closer look: the link may have been called bypassing the ad. Click IDs are covered in detail in fbclid, gclid, ttclid, yclid: what these parameters are.
What not to do
- Do not kill the campaign at the first suspicion. First check the offer, the form and the tracking: technical breakdowns produce empty clicks too. A dead offer or a broken postback looks exactly like fraud in the stats.
- Do not set a "one click per IP" limit blindly. You will cut repeat visits from real people who come back to place an order.
- Do not block whole mobile subnets. Thousands of subscribers sit behind them, and along with one clicker you will cut off buyers.
- Do not judge by the pass rate. If most visits reach the offer, that does not mean there is no fraud, and vice versa. The pass rate depends on the source; the warning sign is only when almost nobody gets through.
How ArtisanClo helps against click fraud
In ArtisanClo, click fraud protection is made up of several mechanisms.
Clicks from one IP per day. After the set number of clicks from an address, the next visits see the White Page. Every visit counts, including reloads. Addresses on the IP whitelist skip this check, which is handy for your own tests.
Unique visitor. The uniqueness window is set from one hour to thirty days; recognition is by IP or by IP and browser. In modes with the tracker, a repeat lead from the same visitor via another click within the window goes to Trash marked "duplicate" and does not replace the first.
Network, browser and behavior checks. Data centers, VPNs, headless browsers, missing JavaScript, unnatural interaction — everything that sets a botnet apart from people.
IP blacklist. Addresses and subnets can be blocked right from the click log, with the icon next to the address or in bulk. A click from an address on your list does not count toward the trial limit.
Data for decisions. The click log shows the address, network, ISP, device, time and decision reason for every visit, and exports to XLSX. In modes with the tracker, ArtisanClo counts cost, revenue, profit and ROI, and the Money by slice report breaks them down by parameter, for example by zone ID. If you just want to assess a source without filtering, Tracker mode with the PHP file lets everyone through to the offer but flags bots: the report shows what share of paid traffic was bots.
Alerts. If too small a share of visits reaches the offer over a day, or the pass rate drops sharply, you get a notification: that is often a sign the rules are cutting real people along with the fraud.
More on calculating money in how to calculate profit and ROI, and the full feature list on the features page.
How to estimate the damage from click fraud
A simple calculation to understand the scale of the problem. Say, for illustration:
- you bought 1,000 clicks at $0.30 — $300 spent;
- the filter weeded out 250 visits with signs of fraud and bots;
- so about $75 went on traffic that could never convert.
That number is an argument both for a request to the platform and for a decision: turn off the source, exclude placements or negotiate a different price. Without a filter and a log you would only see "CR dropped", with no idea why.
In short
Click fraud is clicks made to spend your budget: by competitors, dishonest publishers, botnets and click farms. You cannot cancel the charge for a click, but you can keep fraud off the offer, see where it comes from, block addresses and placements and request a refund. A per-address click limit, visitor uniqueness, browser checks, a blacklist and placement reports together bring the damage down to a manageable level.



